Open Source · MIT · Debian/Ubuntu
HARDN-XDR

Linux Hardening &
Extended Detection

[DEMO]

HARDN is a public demonstration of the full HARDN-XDR enterprise solution. It showcases the core security hardening features. Contact SIG for production HARDN-XDR access.

A comprehensive security hardening system for Debian-based Linux, providing automated configuration, continuous monitoring, and built-in security tooling for cloud-based servers, VPS instances, and local host deployments.

Supported Platforms

Debian 12

Bookworm

Debian 13

Trixie

Ubuntu 22.04

Jammy LTS

Ubuntu 24.04

Noble LTS

Deployment Targets

Cloud VPS

AWS, GCP, Azure, DigitalOcean

Bare Metal

Physical servers and workstations

Local Host

Developer and on-prem environments

Capabilities

Automated System Hardening

STIG-compliant security configuration applied in a single command. Works on cloud VPS, bare-metal servers, and local host deployments running Debian or Ubuntu.

Lynis Security Scanner

Built-in Lynis integration for in-depth security auditing. Performs system-wide scanning and generates actionable hardening recommendations.

AIDE File Integrity

Advanced Intrusion Detection Environment monitors the filesystem and detects unauthorized changes to critical system files in real time.

Fail2ban Network Protection

Automated intrusion prevention via Fail2ban. Monitors authentication logs and bans IPs showing malicious or brute-force behavior at the network level.

Interactive Service Manager

Menu-driven CLI for complete system control, run individual hardening modules or all at once, execute security tools, and generate compliance reports.

Compliance Reports & Sandbox

On-demand security reports from the built-in CIS compliance meter. Sandbox mode enables network-isolated testing before applying changes to production.

Quick Start
# Clone and build HARDN from source
$ git clone https://github.com/Security-International-Group/HARDN
$ cd HARDN
$ sudo make build
# Run HARDN, launches service manager + SIEM
$ sudo make hardn
[INFO] Launching service manager...
[OK] hardn.service active
[OK] legion-daemon.service active
# Interactive service management
$ sudo hardn-service-manager

Ready to harden your infrastructure?

Download HARDN and run your first STIG scan in under five minutes.